This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirects and ping.exe memory usage [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Browser links are all redirected to bogus sites. The most recent site is for a survey stating that I have been selected for something and click to take the survey. I close the window and it is gone. Then I keep getting a notice from JIT Debugger to debug a script. It refers to: C:\WINDOWS\system32\ping.exe I Attempt to execute (Step into Remote Proceedure Call - even though I am not a techie) just trying to get past this window and the debugger errors out indicating it "can't attach to the process. Access Denied" Path name was C:\WINDOWS\system32\ping.exe. I close the window and it just keeps popping up. I try to stop the ping.exe process and it keeps coming back. The only time when it does not return is if I keep my computer offline. This all seemed to occur following a screen that popped bogus virus scan results a few days ago. I ignored the window and stopped the application that was creating this screen from task manager.

I read the "Are you infected" topic. I downloaded hijack this and included the results below.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:57:37 AM, on 11/25/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17103)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\VideoIQ\VideoIQ View\Server\ServerLiteControl.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\PROGRA~1\McAfee\MSM\McSmtFwk.exe
C:\PROGRA~1\COMMON~1\McAfee\MSC\McUICnt.exe
C:\WINDOWS\System32\ping.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\VS7JIT.EXE
C:\Documents and Settings\Mom & Dad\My Documents\Tom\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110511055143.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [jZZZqhYYCwUVrOt8234A] C:\WINDOWS\system32\Cloud AV 2012v121.exe
O4 - HKLM\..\Run: [h77ffEL8gTZqYCk] C:\Documents and Settings\Mom & Dad\Application Data\dwme.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe monthly (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe monthly (User 'Default user')
O4 - S-1-5-18 Startup: Product Registration.lnk = C:\Program Files\Common Files\LogiShared\eReg\SetPoint\eReg.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Product Registration.lnk = C:\Program Files\Common Files\LogiShared\eReg\SetPoint\eReg.exe (User 'Default user')
O4 - .DEFAULT User Startup: Product Registration.lnk = C:\Program Files\Common Files\LogiShared\eReg\SetPoint\eReg.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193248802906
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://datatel.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Update Service (gupdate1c9ae663575fa52) (gupdate1c9ae663575fa52) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: VideoIQ Server Control Service (LiteServerControlService) - VideoIQ, Inc. - C:\Program Files\VideoIQ\VideoIQ View\Server\ServerLiteControl.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

–
End of file - 13552 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

RKill

Print out these instructions as we may need to close every window that is open later in the fix.


It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe

Do not reboot your computer after running rkill as the malware programs will start again.
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS, GMER and the log created by aswMBR.exe. :)
Hi Jeff, Thank you so much for picking up my topic. Quick question. I ran rkill.exe and I could see my desktop screen flash/flicker a couple of times and it appeared as though a dos command type dialog opened but it quickly disappeared. I saw this flash when I kicked off the run and then about 10 -15 seconds later when it appeared to be done. No more hour glass and desktop screen flickering. Did it run?
Hi indy670, Yes RKill ran. :) Go ahead and run DDS, GMER and aswMBR. When you get that completed post the logs that are created. Please copy and paste the logs into the replies instead of attaching them. It makes it easier for me to read.
Hi Jeff, Thanks for confirming rkill ran. I ran DDS.scr and nothing happened. I came back after about an hour and there was a DDS window that popped in front of my desktop background, (all desktop icons and tray menu and icons were gone) that said when I close the window I would find the log files you described. I closed the window and my computer went to its normal welcome screen following an idle period. I click on the user profile I always use and my normal desktop returns with no DDS windows. I unchecked the welcome screen from my display profile, then tried to run DDS.com. This did nothing. Then I used a usb flash drive to download DDS.scr and copy it to this PC to run it. It did nothing. I proceeded to run GMER and aswMBR. Both of these ran and the results are below.

Another note: While I was running GMER it was going really slow so I disabled my wireless capability and ended the ping.exe process that had 500,000K of memory. I did this during the GMER Run.

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-30 01:03:38
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e WDC_WD2500JS-00NCB1 rev.10.02E02
Running: gmer.exe; Driver: C:\DOCUME~1\MOM&DA~1\LOCALS~1\Temp\kgtdipob.sys


—- System - GMER 1.0.15 —-

Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB9ED5210]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB9ED5224]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB9ED5250]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB9ED52A6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB9ED51FC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9ED51D4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9ED51E8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB9ED523A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB9ED527C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB9ED5266]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB9ED52D0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB9ED52BC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB9ED5290]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B9ED5294 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B203A 7 Bytes JMP B9ED52AA mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E48 5 Bytes JMP B9ED52C0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetSecurityObject 805C062E 5 Bytes JMP B9ED5280 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB440 5 Bytes JMP B9ED51D8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6CC 5 Bytes JMP B9ED51EC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29E2 5 Bytes JMP B9ED52D4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80622662 7 Bytes JMP B9ED526A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80623B12 7 Bytes JMP B9ED523E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806240F0 5 Bytes JMP B9ED5214 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8062458C 7 Bytes JMP B9ED5228 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8062475C 7 Bytes JMP B9ED5254 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 806254CE 5 Bytes JMP B9ED5200 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text netbt.sys A822E000 7 Bytes [89, 01, 81, 7D, 10, 16, 00]
.text netbt.sys A822E008 49 Bytes [C0, 0F, 85, 36, FF, FF, FF, …]
.text netbt.sys A822E03A 9 Bytes [FF, 75, 08, 89, 7D, F0, E8, …]
.text netbt.sys A822E045 7 Bytes [84, C0, 0F, 84, 5B, D2, 00]
.text netbt.sys A822E04D 95 Bytes [8B, 47, 18, 8B, 70, 0C, 85, …]
.text …
? C:\WINDOWS\system32\DRIVERS\netbt.sys suspicious PE modification

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[136] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[136] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\System32\svchost.exe[256] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 006E0000
.text C:\WINDOWS\System32\svchost.exe[256] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 006E0025
.text C:\WINDOWS\System32\svchost.exe[256] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006E0FE5
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 006D0000
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 006D0FB9
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 006D0FD4
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 006D00A2
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 006D0087
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 006D0FEF
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 006D0F8D
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 006D0FA8
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 006D0F61
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 006D0F72
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006D011F
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 006D006C
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 006D0025
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 006D00C9
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 006D005B
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 006D0036
.text C:\WINDOWS\System32\svchost.exe[256] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 006D00FA
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0071001B
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0071006C
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00710FC0
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00710000
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00710051
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00710FE5
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00710FA5
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [91, 88]
.text C:\WINDOWS\System32\svchost.exe[256] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0071002C
.text C:\WINDOWS\System32\svchost.exe[256] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00700058
.text C:\WINDOWS\System32\svchost.exe[256] msvcrt.dll!system 77C293C7 5 Bytes JMP 00700047
.text C:\WINDOWS\System32\svchost.exe[256] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00700022
.text C:\WINDOWS\System32\svchost.exe[256] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00700000
.text C:\WINDOWS\System32\svchost.exe[256] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00700FD7
.text C:\WINDOWS\System32\svchost.exe[256] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00700011
.text C:\WINDOWS\System32\svchost.exe[256] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006F0000
.text C:\WINDOWS\System32\svchost.exe[256] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00760FEF
.text C:\WINDOWS\System32\svchost.exe[256] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 0076000A
.text C:\WINDOWS\System32\svchost.exe[256] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00760FD4
.text C:\WINDOWS\System32\svchost.exe[256] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 00760FB9
.text C:\WINDOWS\System32\svchost.exe[272] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 006E000A
.text C:\WINDOWS\System32\svchost.exe[272] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 006E0025
.text C:\WINDOWS\System32\svchost.exe[272] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006E0FEF
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 006D0000
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 006D0082
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 006D0F8D
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 006D0F9E
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 006D0FB9
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 006D0FE5
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 006D0F66
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 006D00AE
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 006D0F30
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 006D0F4B
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006D0F1F
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 006D0FD4
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 006D001B
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 006D009D
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 006D0047
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 006D002C
.text C:\WINDOWS\System32\svchost.exe[272] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 006D00BF
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00710FB9
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00710043
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00710FD4
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00710FE5
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00710F86
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00710000
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00710F97
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [91, 88]
.text C:\WINDOWS\System32\svchost.exe[272] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00710FA8
.text C:\WINDOWS\System32\svchost.exe[272] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00700F9C
.text C:\WINDOWS\System32\svchost.exe[272] msvcrt.dll!system 77C293C7 5 Bytes JMP 00700FAD
.text C:\WINDOWS\System32\svchost.exe[272] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0070001D
.text C:\WINDOWS\System32\svchost.exe[272] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00700000
.text C:\WINDOWS\System32\svchost.exe[272] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00700FD2
.text C:\WINDOWS\System32\svchost.exe[272] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00700FE3
.text C:\WINDOWS\System32\svchost.exe[272] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006F0FE5
.text C:\WINDOWS\System32\svchost.exe[272] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00790000
.text C:\WINDOWS\System32\svchost.exe[272] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00790FE5
.text C:\WINDOWS\System32\svchost.exe[272] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00790FD4
.text C:\WINDOWS\System32\svchost.exe[272] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 00790FC3
.text C:\WINDOWS\system32\svchost.exe[304] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BF000A
.text C:\WINDOWS\system32\svchost.exe[304] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BF0FCA
.text C:\WINDOWS\system32\svchost.exe[304] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE007A
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0F8F
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE0069
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE0058
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE002C
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE00BC
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE0F74
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE00E1
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE0F48
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE0F2D
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE0047
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE0011
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE009F
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0FC0
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE0FD1
.text C:\WINDOWS\system32\svchost.exe[304] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE0F59
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C10040
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C10076
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C1002F
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C10FEF
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C1005B
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C1000A
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00C10FB9
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [E1, 88] {LOOPZ 0xffffffffffffff8a}
.text C:\WINDOWS\system32\svchost.exe[304] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C10FD4
.text C:\WINDOWS\system32\svchost.exe[304] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C00031
.text C:\WINDOWS\system32\svchost.exe[304] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C00F9C
.text C:\WINDOWS\system32\svchost.exe[304] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C00FD2
.text C:\WINDOWS\system32\svchost.exe[304] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C00000
.text C:\WINDOWS\system32\svchost.exe[304] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C00FB7
.text C:\WINDOWS\system32\svchost.exe[304] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C00FEF
.text C:\WINDOWS\system32\services.exe[744] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[744] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00040FE5
.text C:\WINDOWS\system32\services.exe[744] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0004001B
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D30FEF
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D30F52
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D30F63
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D30F80
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D3003D
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D30022
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D30F1A
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D30F2B
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D300A9
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D30098
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D300BA
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D30F9B
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D30000
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D30062
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D30FB6
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D30011
.text C:\WINDOWS\system32\services.exe[744] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D3007D
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0007002F
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00070076
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00070014
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00070FDE
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00070065
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0007004A
.text C:\WINDOWS\system32\services.exe[744] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00070FC3
.text C:\WINDOWS\system32\services.exe[744] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00060F81
.text C:\WINDOWS\system32\services.exe[744] msvcrt.dll!system 77C293C7 5 Bytes JMP 00060F9C
.text C:\WINDOWS\system32\services.exe[744] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00060FD2
.text C:\WINDOWS\system32\services.exe[744] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[744] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00060FB7
.text C:\WINDOWS\system32\services.exe[744] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060FE3
.text C:\WINDOWS\system32\services.exe[744] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\lsass.exe[756] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00E10FE5
.text C:\WINDOWS\system32\lsass.exe[756] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00E1001B
.text C:\WINDOWS\system32\lsass.exe[756] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00E10000
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FF0075
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FF0064
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FF0F8A
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FF0FA5
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FF0036
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FF0F52
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FF009A
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FF00E1
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FF00D0
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FF00F2
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FF0047
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FF000A
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FF0F6F
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FF0FCA
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FF001B
.text C:\WINDOWS\system32\lsass.exe[756] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FF00B5
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FE003D
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FE0FA2
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FE002C
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FE0069
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00FE0FD1
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [1E, 89]
.text C:\WINDOWS\system32\lsass.exe[756] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FE004E
.text C:\WINDOWS\system32\lsass.exe[756] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E40067
.text C:\WINDOWS\system32\lsass.exe[756] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E40FD2
.text C:\WINDOWS\system32\lsass.exe[756] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E40FE3
.text C:\WINDOWS\system32\lsass.exe[756] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E40000
.text C:\WINDOWS\system32\lsass.exe[756] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E40042
.text C:\WINDOWS\system32\lsass.exe[756] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E4001D
.text C:\WINDOWS\system32\lsass.exe[756] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E30000
.text C:\WINDOWS\system32\lsass.exe[756] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00E20FEF
.text C:\WINDOWS\system32\lsass.exe[756] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00E2000A
.text C:\WINDOWS\system32\lsass.exe[756] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00E20FD4
.text C:\WINDOWS\system32\lsass.exe[756] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 00E2002F
.text C:\WINDOWS\system32\svchost.exe[920] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00AA0FE5
.text C:\WINDOWS\system32\svchost.exe[920] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00AA0FCA
.text C:\WINDOWS\system32\svchost.exe[920] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00AA000A
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B20FEF
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B20F66
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B20065
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B20F8D
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B2004A
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B20FC3
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B20098
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B20087
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B200C4
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B20F35
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B200DF
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B20FA8
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B20FDE
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B20076
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B20039
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B2001E
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B200B3
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00AD0FC0
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00AD0040
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00AD001B
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00AD000A
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00AD0F83
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00AD0FEF
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00AD0F9E
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [CD, 88] {INT 0x88}
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00AD0FAF
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00AC0053
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!system 77C293C7 5 Bytes JMP 00AC0FD2
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00AC001D
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00AC0000
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00AC0038
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00AC0FE3
.text C:\WINDOWS\system32\svchost.exe[920] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00AB0000
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00EA0FEF
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00EA000A
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00EA0FD4
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E20000
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E20F77
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E20F88
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E2006C
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E2005B
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E20FAF
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E2008E
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E20F46
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E200C4
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E200A9
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E20F10
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E20036
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E20FE5
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E2007D
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E20FC0
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E2001B
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E20F2B
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B3003D
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B3007D
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B3002C
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B3001B
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B30FC0
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B30000
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00B30058
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B30FDB
.text C:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B2004C
.text C:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B20FC1
.text C:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B20016
.text C:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B20FEF
.text C:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B20027
.text C:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B20FDE
.text C:\WINDOWS\system32\svchost.exe[1028] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B10FEF
.text C:\WINDOWS\system32\svchost.exe[1028] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00B00000
.text C:\WINDOWS\system32\svchost.exe[1028] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00B00FEF
.text C:\WINDOWS\system32\svchost.exe[1028] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00B00FD4
.text C:\WINDOWS\system32\svchost.exe[1028] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 00B0002F
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 01CD0000
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 01CD002C
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 01CD001B
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 01A4000A
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0176000C
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02A30FEF
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02A3004C
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02A30F61
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02A30F72
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02A30F83
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02A30025
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02A30F30
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02A30078
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02A30F0B
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02A300A4
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02A30EF0
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02A30FA8
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02A30FDE
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02A3005D
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02A30014
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02A30FC3
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02A30093
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02A20FA8
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02A20014
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02A20FC3
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02A20FD4
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02A20F61
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02A20FEF
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 02A20F72
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C2, 8A]
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02A20F83
.text C:\WINDOWS\System32\svchost.exe[1056] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01D0007F
.text C:\WINDOWS\System32\svchost.exe[1056] msvcrt.dll!system 77C293C7 5 Bytes JMP 01D00064
.text C:\WINDOWS\System32\svchost.exe[1056] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01D00038
.text C:\WINDOWS\System32\svchost.exe[1056] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01D00000
.text C:\WINDOWS\System32\svchost.exe[1056] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01D00053
.text C:\WINDOWS\System32\svchost.exe[1056] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01D0001D
.text C:\WINDOWS\System32\svchost.exe[1056] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01CF0000
.text C:\WINDOWS\System32\svchost.exe[1056] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 01CE0000
.text C:\WINDOWS\System32\svchost.exe[1056] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 01CE0FDB
.text C:\WINDOWS\System32\svchost.exe[1056] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 01CE0011
.text C:\WINDOWS\System32\svchost.exe[1056] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 01CE002C
.text C:\WINDOWS\system32\svchost.exe[1104] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00630FEF
.text C:\WINDOWS\system32\svchost.exe[1104] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00630FC3
.text C:\WINDOWS\system32\svchost.exe[1104] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00630FDE
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00660000
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0066007D
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00660062
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00660051
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00660040
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00660011
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00660F46
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00660F57
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 006600A9
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00660F10
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006600C4
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00660F94
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00660FE5
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0066008E
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00660FAF
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00660FC0
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00660F2B
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0065002C
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00650FA5
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00650FDB
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00650011
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00650062
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00650FC0
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [85, 88]
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00650047
.text C:\WINDOWS\system32\svchost.exe[1104] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00640FA8
.text C:\WINDOWS\system32\svchost.exe[1104] msvcrt.dll!system 77C293C7 5 Bytes JMP 00640FC3
.text C:\WINDOWS\system32\svchost.exe[1104] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00640FDE
.text C:\WINDOWS\system32\svchost.exe[1104] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00640FEF
.text C:\WINDOWS\system32\svchost.exe[1104] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00640033
.text C:\WINDOWS\system32\svchost.exe[1104] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00640018
.text C:\WINDOWS\system32\svchost.exe[1148] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00990000
.text C:\WINDOWS\system32\svchost.exe[1148] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0099001B
.text C:\WINDOWS\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00990FE5
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009D0000
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009D0089
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009D006E
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009D0F94
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009D0FA5
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009D0051
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009D00B7
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009D00A6
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009D00C8
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009D0F39
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009D0F0A
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009D0FC0
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009D0011
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009D0F79
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009D0FDB
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009D002C
.text C:\WINDOWS\system32\svchost.exe[1148] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009D0F54
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009C0FB9
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009C0F61
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009C0FD4
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009C000A
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009C0F72
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009C0FEF
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 009C0F83
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [BC, 88]
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009C0F9E
.text C:\WINDOWS\system32\svchost.exe[1148] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009B0FAD
.text C:\WINDOWS\system32\svchost.exe[1148] msvcrt.dll!system 77C293C7 5 Bytes JMP 009B0038
.text C:\WINDOWS\system32\svchost.exe[1148] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009B0FD2
.text C:\WINDOWS\system32\svchost.exe[1148] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009B000C
.text C:\WINDOWS\system32\svchost.exe[1148] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009B001D
.text C:\WINDOWS\system32\svchost.exe[1148] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009B0FE3
.text C:\WINDOWS\system32\svchost.exe[1148] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009A0000
.text C:\WINDOWS\system32\svchost.exe[1148] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 009F000A
.text C:\WINDOWS\system32\svchost.exe[1148] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 009F001B
.text C:\WINDOWS\system32\svchost.exe[1148] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 009F0FEF
.text C:\WINDOWS\system32\svchost.exe[1148] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 009F004A
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 009D0000
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 009D0FE5
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 009D001B
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A10000
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A10FA8
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A10093
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A10082
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A10FB9
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A10047
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A10F7C
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A100B8
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A10104
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A100DF
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A10F50
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A10FCA
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A10011
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A10F97
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A10036
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A10FDB
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A10F61
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A00036
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A00FA8
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A00025
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A00FEF
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A00FB9
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A00000
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A00FD4
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C0, 88]
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A0005B
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009F0FB7
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!system 77C293C7 5 Bytes JMP 009F0038
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009F0FC8
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009F0000
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009F001D
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009F0FE3
.text C:\WINDOWS\system32\svchost.exe[1188] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009E0FEF
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00B70000
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00B70011
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00B70FE5
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 00B70FC0
.text C:\WINDOWS\system32\svchost.exe[1504] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00900FEF
.text C:\WINDOWS\system32\svchost.exe[1504] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00900011
.text C:\WINDOWS\system32\svchost.exe[1504] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00900000
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE0FE5
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE0F52
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0F63
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE0047
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE0F8A
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE0FA5
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE0F24
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE006C
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE0098
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE0087
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE00A9
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE002C
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE0F41
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0FC0
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE0011
.text C:\WINDOWS\system32\svchost.exe[1504] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE0F09
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BD001B
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BD0F80
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BD0FD4
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BD000A
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BD003D
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BD0FE5
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00BD002C
.text C:\WINDOWS\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BD0FA5
.text C:\WINDOWS\system32\svchost.exe[1504] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00930F7F
.text C:\WINDOWS\system32\svchost.exe[1504] msvcrt.dll!system 77C293C7 5 Bytes JMP 00930F90
.text C:\WINDOWS\system32\svchost.exe[1504] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00930FC6
.text C:\WINDOWS\system32\svchost.exe[1504] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00930000
.text C:\WINDOWS\system32\svchost.exe[1504] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00930FA1
.text C:\WINDOWS\system32\svchost.exe[1504] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00930FE3
.text C:\WINDOWS\system32\svchost.exe[1504] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00910000
.text C:\WINDOWS\system32\svchost.exe[1504] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00910025
.text C:\WINDOWS\system32\svchost.exe[1504] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00910036
.text C:\WINDOWS\system32\svchost.exe[1504] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 00910047
.text C:\WINDOWS\system32\svchost.exe[1504] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00920FEF
.text C:\WINDOWS\system32\svchost.exe[1728] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B40FEF
.text C:\WINDOWS\system32\svchost.exe[1728] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B40FCD
.text C:\WINDOWS\system32\svchost.exe[1728] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B40FDE
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B7000A
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B70F83
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B70082
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B70F9E
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B7005B
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B70040
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B700AE
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B7009D
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B700E4
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B700D3
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B700F5
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B70FB9
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B70FE5
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B70F72
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B70FD4
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B7001B
.text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B70F55
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B60047
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B6007A
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B60036
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B6001B
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B60FBD
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B6000A
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00B60069
.text C:\WINDOWS\system32\svchost.exe[1728] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B60058
.text C:\WINDOWS\system32\svchost.exe[1728] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B50F90
.text C:\WINDOWS\system32\svchost.exe[1728] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B50FAB
.text C:\WINDOWS\system32\svchost.exe[1728] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B50011
.text C:\WINDOWS\system32\svchost.exe[1728] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B50FE3
.text C:\WINDOWS\system32\svchost.exe[1728] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B50FBC
.text C:\WINDOWS\system32\svchost.exe[1728] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B50000
.text C:\WINDOWS\system32\svchost.exe[1740] ntdll.dll!NtCreateFile 7C90D0AE 3 Bytes JMP 01910FEF
.text C:\WINDOWS\system32\svchost.exe[1740] ntdll.dll!NtCreateFile + 4 7C90D0B2 1 Byte [85]
.text C:\WINDOWS\system32\svchost.exe[1740] ntdll.dll!NtCreateProcess 7C90D14E 3 Bytes JMP 01910000
.text C:\WINDOWS\system32\svchost.exe[1740] ntdll.dll!NtCreateProcess + 4 7C90D152 1 Byte [85]
.text C:\WINDOWS\system32\svchost.exe[1740] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 3 Bytes JMP 01910FD4
.text C:\WINDOWS\system32\svchost.exe[1740] ntdll.dll!NtProtectVirtualMemory + 4 7C90D6F2 1 Byte [85]
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01960FE5
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01960F68
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01960053
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01960042
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01960025
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01960FA8
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0196006E
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01960F26
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01960EF7
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 0196009A
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01960EE6
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01960F83
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0196000A
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01960F4D
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01960FB9
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01960FD4
.text C:\WINDOWS\system32\svchost.exe[1740] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01960089
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01950040
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0195006C
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01950FEF
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01950025
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01950FB9
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01950000
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0195005B
.text C:\WINDOWS\system32\svchost.exe[1740] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01950FD4
.text C:\WINDOWS\system32\svchost.exe[1740] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01940FB2
.text C:\WINDOWS\system32\svchost.exe[1740] msvcrt.dll!system 77C293C7 5 Bytes JMP 0194003D
.text C:\WINDOWS\system32\svchost.exe[1740] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01940FDE
.text C:\WINDOWS\system32\svchost.exe[1740] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0194000C
.text C:\WINDOWS\system32\svchost.exe[1740] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01940FCD
.text C:\WINDOWS\system32\svchost.exe[1740] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01940FEF
.text C:\WINDOWS\system32\svchost.exe[1740] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0193000A
.text C:\WINDOWS\system32\svchost.exe[1740] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 01920FEF
.text C:\WINDOWS\system32\svchost.exe[1740] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 01920FDE
.text C:\WINDOWS\system32\svchost.exe[1740] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 01920014
.text C:\WINDOWS\system32\svchost.exe[1740] WININET.dll!InternetOpenUrlW 3D9984A1 5 Bytes JMP 01920025
.text C:\WINDOWS\Explorer.EXE[3188] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 06A2000A
.text C:\WINDOWS\Explorer.EXE[3188] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 06A3000A
.text C:\WINDOWS\Explorer.EXE[3188] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 06A1000C
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A0FAF
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A0062
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A0FCA
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A0FE5
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A003D
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A0000
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A002C
.text C:\WINDOWS\Explorer.EXE[3188] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A001B
.text C:\WINDOWS\Explorer.EXE[3188] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002B0056
.text C:\WINDOWS\Explorer.EXE[3188] msvcrt.dll!system 77C293C7 5 Bytes JMP 002B003B
.text C:\WINDOWS\Explorer.EXE[3188] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002B0FC1
.text C:\WINDOWS\Explorer.EXE[3188] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002B0FE3
.text C:\WINDOWS\Explorer.EXE[3188] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002B0020
.text C:\WINDOWS\Explorer.EXE[3188] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002B0FD2
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 03AA000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 03AB000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 03A9000C
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3528F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E352877 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3528BB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E352803 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E35283D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352931 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E201762 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4364] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E352AF3 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\WINDOWS\System32\ping.exe[5924] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA000A
.text C:\WINDOWS\System32\ping.exe[5924] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00BB000A
.text C:\WINDOWS\System32\ping.exe[5924] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A5000A
.text C:\WINDOWS\System32\ping.exe[5924] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00A6000A
.text C:\WINDOWS\System32\ping.exe[5924] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A4000C
.text C:\WINDOWS\System32\ping.exe[5924] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 00BE000A
.text C:\WINDOWS\System32\ping.exe[5924] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 00BF000A
.text C:\WINDOWS\System32\ping.exe[5924] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 00C0000A
.text C:\WINDOWS\System32\ping.exe[5924] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00BD000A

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

—- Modules - GMER 1.0.15 —-

Module (noname) (*** hidden *** ) A831D000-A8336000 (102400 bytes)

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\$NtUninstallKB51222$\1312572467 0 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059 0 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\bckfg.tmp 764 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\cfg.ini 207 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\keywords 37 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\kwrd.dll 223744 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\L 0 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\L\gncafwla 162816 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\lsflt7.ver 5176 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\U 0 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\U\00000001.@ 1536 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\U\80000000.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB51222$\3999082059\U\80000032.@ 98304 bytes

—- EOF - GMER 1.0.15 —-


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-30 01:04:47
—————————–
01:04:47.218 OS Version: Windows 5.1.2600 Service Pack 3
01:04:47.218 Number of processors: 2 586 0xF0D
01:04:47.218 ComputerName: MYERS-FAMILY UserName: Mom & Dad
01:04:47.843 Initialize success
01:06:07.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
01:06:07.000 Disk 0 Vendor: WDC_WD2500JS-00NCB1 10.02E02 Size: 238475MB BusType: 3
01:06:09.062 Disk 0 MBR read successfully
01:06:09.062 Disk 0 MBR scan
01:06:09.062 Disk 0 Windows XP default MBR code
01:06:09.078 Disk 0 scanning sectors +488392065
01:06:09.343 Disk 0 scanning C:\WINDOWS\system32\drivers
01:06:42.046 File: C:\WINDOWS\system32\drivers\netbt.sys **SUSPICIOUS**
01:07:01.875 Service scanning
01:07:02.812 Modules scanning
01:07:35.500 Module: C:\WINDOWS\system32\DRIVERS\netbt.sys **SUSPICIOUS**
01:07:47.609 Disk 0 trace - called modules:
01:07:47.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x89f69f10]<<
01:07:47.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ac95ab8]
01:07:47.640 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> [0x8a2d9f08]
01:07:47.656 \Driver\00001554[0x8a3512e0] -> IRP_MJ_CREATE -> 0x89f69f10
01:07:47.656 Scan finished successfully
06:05:42.359 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Mom & Dad\My Documents\Tom\Personal Word Documents\MBR.dat"
06:05:42.359 The log file has been saved successfully to "C:\Documents and Settings\Mom & Dad\My Documents\Tom\Personal Word Documents\aswMBR.txt"


Let me know if I need to try something different with DDS. I work all day so I won't get back to this until evening hours. I really appreciate your help.
Thanks.
Hi indy670,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

It seems that you have the ZeroAccess Rootkit on your system which is an especially nasty piece of malware. While it is possible that your system is cleanable, we may have to format and re-install your operating system regardless of what we do and this may take quite some time to clean. As a precaution, if you choose to clean, you may even lose internet access with the system temporarily until we have completed the cleaning.

If you would like to format and reinstall your Operating System please let me know and I can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-

If you have chosen to attempt to clean please post the logs created by TDSSKiller and OTL. :)
Hi Jeff. That is not encouraging news. I have been backing up the infected computer with a portable USB drive. I have been backing up the folders and files in this path C:\Documents and Settings\Mom & Dad\My Documents\ Nothing above this level. Is the problem now resident on the portable USB Drive? I would like to recover certain files if I reinstall the op sys and apps, i.e., outlook.pst N2K, pictures, word docs, itunes library, etc. Depending on your response to the above, I can decide what path to take. I don't mean to put you on the spot but If it was yours, what would you do? Indy670
Hi indy670,

I don't mean to put you on the spot but If it was yours, what would you do?

This is just my opinion…If it were my computer I would format and re-install the operating system. This infection is exceptionally nasty and infects all computers seemingly differently. You can feel safe in saving your documents, music, photos and such but nothing with a .exe extension at all. However have no doubt if you decide to attempt a cleaning I will do my very best. :)
OK Jeff. Thanks for the opinion. I would like to reformat and re-install. I would appreciate your help with this. Regarding the saving of files: What if the backups I have been doing to my portable USB drive contain some .exe files? I have not checked yet, but if there are some .exe files on the portable drive am I safe to pull (copy) my docs, pics, music etc from the portable drive to my computer once I get the computer reinstalled? Indy670
Hi indy670,

I would like to reformat and re-install

Sounds like a plan. :)

I think for something like this you would be better served posting a new topic in the Windows forum found here. The techs there are exceptional and will be able to walk you through this better than I. Be sure to put a link to the topic here in the topic you start in the Windows forum so they can take a look at what we see here.

As for your items on your USB drive, you can feel comfortable removing and saving documents, music and photos from there for re-installation back onto your system after the new operating system is installed. Anything else I would be wary of personally. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI